hono is vulnerable to Improper Authorization
48
Medium Risk
The Lambda@Edge adapter maps CloudFront multi-value request headers using Headers.set for each value. Repeated values overwrite earlier ones so only the last entry reaches application middleware. Access control or auditing that depends on the full X-Forwarded-For, Forwarded, or Via chain receives incomplete data. The adapter now appends each repeated header value so the full chain is preserved.
You are affected if you are using a version that falls within the vulnerable range. and you deploy on AWS Lambda@Edge and rely on multi-value request headers such as X-Forwarded-For for access control or auditing.
hono is vulnerable to Improper Authorization in versions 0.0.1 - 4.12.24.
Upgrade the hono library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant